A critical arbitrary file read flaw tracked as CVE-2026-59774 was disclosed in Gitea and Forgejo, allowing attackers to retrieve local files from vulnerable servers through the markup rendering feature. The issue stems from unsafe handling of Org-mode #+INCLUDE directives in the go-org library, which can resolve absolute filesystem paths when the default ReadFile callback is not overridden. In Gitea, the bug was demonstrated against public repository markup rendering and was reported to affect versions 1.27.0 and 1.27.1, with proof-of-concept requests exposing files such as /etc/passwd.
Public exploit support quickly followed for both platforms. A Nuclei template was published to detect the Gitea exposure via crafted POST requests to the repository markup endpoint, while a Metasploit auxiliary module was released for Forgejo that targets POST /api/v1/markup, extracts included file contents from rendered HTML, and can save retrieved files locally. Forgejo was reported vulnerable in versions 7.0 through 15.0.5 and 16.0.0 through 16.0.1, with fixes available in 15.0.6 and 16.0.2; demonstration output showed successful reads of files including /etc/hosts.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
A Metasploit auxiliary module, auxiliary/gather/forgejo_orgmode_fileread_cve_2026_59774, was submitted to exploit CVE-2026-59774 by authenticating to Forgejo, posting crafted org-mode content to /api/v1/markup, and extracting included file contents from the HTML response. Example output showed successful reading of /etc/hosts from a Forgejo 15.0.5 target and saving the retrieved file locally.
A nuclei template named gitea-public-repo-exposure.yaml was submitted to detect CVE-2026-59774 by targeting the vulnerable Gitea markup endpoint. Validation output in the submission showed a successful match against a test instance.
A reference described CVE-2026-59774 as a critical unauthenticated arbitrary file read in Gitea 1.27.0 and 1.27.1 via the public repository markup rendering endpoint. The proof of concept used crafted Org-mode input with a #+INCLUDE directive to read local files such as /etc/passwd from the server.
CVE-2026-59774 was described as an arbitrary file read flaw in Forgejo's markup rendering API caused by the go-org library's default ReadFile callback not being overridden, allowing org-mode #+INCLUDE directives to read absolute paths on the server. The affected versions were reported as 7.0 through 15.0.5 and 16.0.0 through 16.0.1, with fixes available in 15.0.6 and 16.0.2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.